GDPR · EU and UK
GDPR data protection
awareness for your people.
GDPR requires appropriate technical and organisational security for personal data, including a process for regularly testing and evaluating how well those measures work, and gives the data protection officer the task of awareness-raising and training for staff involved in processing.
- Framework
- GDPR, Regulation (EU) 2016/679, and UK GDPR
- Security
- Article 32, including regular testing of effectiveness
- Staff
- Article 39(1)(b): awareness-raising and training of staff
- Breaches
- Notify the supervisory authority within 72 hours (Article 33)
What GDPR says about people
Security has to be tested,
not just written down.
The articles below are in force.
| Provision | What it says | Status |
|---|---|---|
| Article 32(1) | Appropriate technical and organisational measures ensure a level of security appropriate to the risk. | In force |
| Article 32(1)(d) | A process for regularly testing, assessing and evaluating the effectiveness of those measures. | In force |
| Article 39(1)(b) | The data protection officer’s tasks include awareness-raising and training of staff involved in processing. | In force |
| Article 33(1) | Notify the supervisory authority of a personal data breach within 72 hours of becoming aware of it. | In force |
| UK Data (Use and Access) Act 2025 | Most of the UK’s data protection changes commenced on 5 February 2026. | In force in the UK |
Breaches start with people
One click can
expose a customer list.
A credential entered on a fake login page, or a file sent to the wrong person, can become a personal data breach.
Data protection awareness
- Data protection policy acknowledged
- Micro-lesson: handling personal data safely
- Credential-capture simulation
- Phishing Reporter in every mailbox
- Evidence review with the DPO
Illustrative programme.
Expectation to record
Awareness you can
show your DPO.
Staff trained on data protection.
LMS completions, assessments and certificates.
Staff accept your data policies.
Dated records per person and version.
Staff tested against phishing.
Outcomes per channel, team and campaign.
Staff report suspicious messages.
Phishing Reporter logs with automated analysis.
Policy Manager records employee policy acknowledgement. It is not a consent-management system for customer or data-subject consent. KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.
This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.
Primary sources
What this page is based on.
Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.
- Regulation (EU) 2016/679 (GDPR)Articles 32, 33 and 39
- Data (Use and Access) Act 2025Royal Assent 19 June 2025 · most provisions from 5 February 2026
- ICO statement on commencement of the Data (Use and Access) ActFebruary 2026
Questions buyers ask
Frequently asked questions.
Is the 72-hour breach deadline changing?
Not yet. The European Commission’s Digital Omnibus proposal would change breach reporting, but it is still being negotiated. Today the deadline under Article 33 is 72 hours.
What changed in the UK?
The Data (Use and Access) Act 2025 amended UK data protection law, with most changes in force from 5 February 2026. The security duty and 72-hour breach reporting remain.
Does KeenSec make us compliant with GDPR?
No tool makes you compliant on its own. KeenSec helps you evidence employee data protection awareness; your DPO, counsel and supervisory authority decide compliance.
Is Policy Manager a consent-management tool?
No. It records employee acknowledgement of internal policies. Customer or data-subject consent needs a separate consent process.
Let’s connect the dots
Protect the data
by preparing the people.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo